# Python
__pycache__/
*.py[cod]
*$py.class
*.egg-info/
.pytest_cache/
.coverage
htmlcov/
build/
dist/
.venv/
venv/

# Node
node_modules/
.next/
dist/
out/

# Editors
.DS_Store
.vscode/
.idea/

# Secrets — never commit. .env.example is the tracked template.
.env
.env.*
!.env.example

# Local state
*.local
.env.local
.env.*.local

# Run output (traces, results, findings).
# LEADING SLASH IS LOAD-BEARING: an unanchored `runs/` matches a directory named
# runs at ANY depth, which silently excluded dashboard/app/app/runs/[runId]/ —
# the console's results route. It built fine locally because the file was on
# disk, and 404'd on every deployment because git had never seen it. Three
# separate "fixes" went to a file the deployment did not have.
/runs/
/runs/.demo-logs/
~/.mcp_eval/
acme_storage.db

# `litmus_service.worldgen.gates` writes materialized worlds here, relative to
# wherever it is run from. Five worlds plus their per-template oracle/decoy
# copies is ~143MB of SQLite, and this sat untracked-but-not-ignored while the
# library lived under a deploy path: the pipeline's own documented command
# dirtied the tree, and `git add -A` would have committed the lot (§5 (122)).
pipeline-out/

# Tooling
.claude/
.claude/scheduled_tasks.lock

# generated per-issue repro suites (issueloop/repro.py) — now under legacy/
legacy/src/mcp_eval/tasks/suites/repro_*.json

# litmus-service runtime artifacts
service/data/
service/.venv/

# experiment scratch (regenerated deterministically by each harness)
experiments/results/*_work/
experiments/harness/*_work/

# Local demo workspace data (service --data-dir), never committed.
/.demo-data/

# The CLI's working directory, wherever it runs. On this machine it holds
# worlds `litmus mock` materialises from a bundle (regenerated on demand). On a
# CUSTOMER's machine the same directory holds their captured sessions and
# `pushed.json` — their traffic — so this must never be a thing anyone commits
# by habit.
/.litmus/

# Assembled customer exports (`litmus export`): regenerated from the pins, never committed.
/exports/

# Terraform working state. `.terraform/` is a local cache of providers and
# module links, `*.tfstate` can hold secrets in clear, and `.terraform.lock.hcl`
# is the one thing here worth tracking (it pins provider versions) so it is
# deliberately NOT ignored. Added 2026-09-16 after `terraform init` dropped
# .terraform/modules/modules.json into a commit.
.terraform/
*.tfstate
*.tfstate.*
*.tfvars
!*.tfvars.example
crash.log

# Live-loop trial bodies (E12). The scorecard and the counts summary beside them
# are committed; the per-trial traces are not — they hold the fictional store's
# items and the model's answers, and the repo's rule from the phase-5 note is
# counts, never bodies.
experiments/results/langfuse/loop-*/*
!experiments/results/langfuse/loop-*/scorecard.md

# Customer corpora pulled from the workspace for a harness to read (X93 and
# after). NOT under experiments/results/: that tree is scanned in full by
# `test_no_committed_result_carries_identity`, and a corpus belongs on neither
# side of that check — it is customer data, cited by evidence id and never
# committed. Regenerated by the harness's own `fetch`.
/.corpus-cache/
